Supabase Read for AI agents
This read-only companion to Supabase lets an agent inspect a project's database, schemas, logs, branches, and Edge Functions without making any changes. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in Supabase Read.
List tables in a schema
List the tables in a project's database schema so a developer can see the current structure.
Query logs for recent errors
Search project logs for recent errors, a safe read-only step before deciding what to fix.
Check cost before running a query
Get the estimated cost of a query and require confirmation before running anything that could be expensive.
21 Supabase Read actions, graded by risk.
Every Supabase Read action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
18Look things up. Allowed by default.
- supabase_read.get_costGet cost
- supabase_read.query_logsQuery logs
- supabase_read.get_projectGet project
- supabase_read.list_tablesList tables
- supabase_read.search_docsSearch docs
- supabase_read.get_advisorsGet advisors
- supabase_read.list_branchesList branches
- supabase_read.list_projectsList projects
- supabase_read.get_project_urlGet project url
- supabase_read.list_extensionsList extensions
- supabase_read.list_migrationsList migrations
- supabase_read.get_organizationGet organization
- supabase_read.get_edge_functionGet edge function
- supabase_read.get_storage_configGet storage config
- supabase_read.list_organizationsList organizations
- supabase_read.list_edge_functionsList edge functions
write
3Create and change things. Allow, or ask the user first.
- supabase_read.execute_sqlExecute sql
- supabase_read.confirm_costConfirm cost
- supabase_read.generate_typescript_typesGenerate typescript types
destructive
0Delete, cancel or archive. Ask first, or deny outright.
- No destructive actions.
Supabase Read in three steps.
- 01Your users connect Supabase ReadThey sign in to Supabase Read on Arc0 Connect, under your brand, and approve the access you ask for.
- 02You set the rulesReads run, and writes like “execute sql” can wait for the user to approve.
- 03Any agent can actYour agent calls Supabase Read through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('supabase_read', { read: 'allow', write: 'ask', // execute_sql destructive: 'deny', }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How Supabase Read connects.
Supabase Read runs its own MCP server behind OAuth. Arc0 registers the client, users approve access on Arc0 Connect, and your agent reaches Supabase Read through the same endpoint, policies and audit log as every other app.
The same Supabase Read connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- OAuth 2.0 (MCP)
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use Supabase Read from any agent.
More databases and spreadsheets apps.
Supabase Read and Arc0, answered.
Can I use Supabase Read with Claude, ChatGPT or Cursor?
Yes. Connect Supabase Read to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Supabase Read actions you allow.
How do users connect Supabase Read?
Supabase Read runs its own MCP server behind OAuth. Arc0 registers the client, users approve access on Arc0 Connect, and your agent reaches Supabase Read through the same endpoint, policies and audit log as every other app.
Which Supabase Read actions can my agent take?
21 in total: 18 read, 3 write and 0 destructive, such as “execute sql”. Your policies decide which of them each agent may call.
Can I make my agent read-only in Supabase Read?
Yes. Allow read actions and deny writes in the Supabase Read policy. Your agent can still look things up, and any write it attempts is blocked and logged.
Can my own backend call Supabase Read too?
Yes. The same Supabase Read connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug Supabase Read into your agent.
Your users connect Supabase Read once, under your brand. Your agent gets 21 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan